PT-2023-5281 · Unknown · Juplink Rx4-1500

Exodus Intelligence

·

Published

2023-07-30

·

Updated

2023-09-22

·

CVE-2023-41030

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Juplink RX4-1500 versions V1.0.2 through V1.0.5
Description The issue is related to the use of hard-coded credentials in the Juplink RX4-1500 WI-FI router's software. This allows unauthenticated attackers to log in to the web interface or telnet service as the user user, potentially leading to privilege escalation. The exploitation can be done remotely.
Recommendations For Juplink RX4-1500 versions V1.0.2 through V1.0.5, consider changing the default credentials to custom, secure ones to prevent unauthorized access. As a temporary workaround, restrict access to the web interface and telnet service until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

BDU:2023-05904
CVE-2023-41030

Affected Products

Juplink Rx4-1500